Categories: Cyber Security News

CISA mixup of IOC domains

Google’s Threat Intelligence Group (GTIG) and Mandiant’s recent Disrupting the GRIDTIDE Global Cyber Espionage Campaign report is great and it has lots of good Indicators of Compromise (IOC). Many of these IOCs had already been shared by CISA in May last year as part of their Alert AA25-141A
Sponsored
titled “Russian GRU Targeting Western Logistics Entities and Technology Companies”.
The IOC overlap between these two reports is surprisingly big, provided that the GTIG report covers a Chinese espionage group while the CISA report covers the Russian GRU unit 26165 (aka APT28 / Fancy Bear).

But some of the domain names in CISA’s report from last year seemed strange. For example, the domain name “accesscan[.]org” doesn’t seem to ever have been registered. The GTIG report, however, contains the very similar domain “accesscam[.]org”. This accesscam domain is registered to the dynamic DNS provider Dynu Systems, whose services are often abused by malicious actors. Is it possible that there are typos in the IOCs published by CISA? I think so.

Another odd domain in CISA’s AA25-141A is “glize[.]com”, which I suspect is a typo from either “giize[.]com” or “gleeze[.]com”. The two latter domains are listed in the GTIG report and both of them also belong to the dynamic DNS provider Dynu Systems. The domain listed in CISA’s alert, on the other hand, appears to be a legit website (archived page from 2024) from the marketing company Glize in Malta.

Sponsored

Glize’s website seems to have disappeared sometime in 2025.

rssfeeds-admin

Recent Posts

We Were Here Tomorrow Trailer Reveals New Setting | Fan Fest 2026

The We Were Here series is the stuff of co-op magic, and at IGN Fan…

10 minutes ago

Smartphone sales could be in for their biggest drop ever

The smartphone industry could experience a record-breaking decline in 2026 as a result of the…

45 minutes ago

Samsung exec confirms you can blame RAM — and other materials — for the Galaxy S26’s higher pricetag

The Samsung Galaxy S26 and S26 Plus are "more of the same for more money,"…

45 minutes ago

FTC declines to enforce a kids privacy law for data collected to verify users’ ages

The Federal Trade Commission is encouraging companies to adopt age verification technologies by announcing it…

45 minutes ago

Zoom Update Scam Infected 1,437 Users to Deploy Surveillance Tools in 12 Days

A cleverly crafted fake Zoom website has silently pushed surveillance software onto Windows machines, infecting…

60 minutes ago

1Campaign Platform Helps Attackers Bypass Google Ads Screening to Show Malicious Ads

A newly uncovered cloaking platform called 1Campaign is giving cybercriminals a powerful tool to push malicious advertisements…

60 minutes ago

This website uses cookies.